fix(deps): update all non-major dependencies#8
Open
renovate[bot] wants to merge 1 commit intomasterfrom
Open
Conversation
9d643a9 to
31105c3
Compare
31105c3 to
de7efc0
Compare
de7efc0 to
211bb25
Compare
1463cba to
05f0907
Compare
6174e46 to
acd7b56
Compare
acd7b56 to
c608a63
Compare
c608a63 to
ac09f47
Compare
ac09f47 to
83c4941
Compare
83c4941 to
8fa7ccd
Compare
8fa7ccd to
3734c15
Compare
3734c15 to
8e0942b
Compare
8e0942b to
cd5567f
Compare
1 task
cd5567f to
a384fa3
Compare
a384fa3 to
5856e18
Compare
88d7a76 to
b6d6bbc
Compare
b6d6bbc to
7ca9842
Compare
7ca9842 to
4483f62
Compare
4483f62 to
079cb39
Compare
079cb39 to
7db6fbd
Compare
7db6fbd to
f6c0b98
Compare
f6c0b98 to
5f66b41
Compare
fcecffc to
e1ddccf
Compare
e1ddccf to
6f49197
Compare
6f49197 to
5a0530f
Compare
5a0530f to
0983f8c
Compare
0983f8c to
116ae1f
Compare
116ae1f to
2dafbe3
Compare
2dafbe3 to
2e31818
Compare
c66e10b to
874f999
Compare
3eaba1e to
db54443
Compare
db54443 to
09efbc0
Compare
9653d7f to
89effb6
Compare
89effb6 to
b31c067
Compare
b31c067 to
b648b71
Compare
b648b71 to
5c87588
Compare
5c87588 to
82283a2
Compare
c5e1470 to
0c57b5e
Compare
0c57b5e to
fc03684
Compare
fc03684 to
1b7916b
Compare
ccb4d55 to
bb56152
Compare
bb56152 to
3b9ecc4
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
^22.0.0-firestore.1.15.5→^22.0.0-firestore.1.15.7^0.23.0→^0.30.2^4.17.1→^4.22.1^3.15.7→^3.24.1^9.20.0→^9.23.314→14.21.312.x→12.22.1210.x→10.24.1^3.14.2→^3.19.3Release Notes
ecomplus/application-sdk (@ecomplus/application-sdk)
v22.0.0-firestore.1.15.7Compare Source
v22.0.0-firestore.1.15.6Compare Source
axios/axios (axios)
v0.30.2Compare Source
What's Changed
maxContentLengthvulnerability fix to v0.x by @FeBe95 in #7034New Contributors
Full Changelog: axios/axios@v0.30.1...v0.30.2
v0.30.1Compare Source
Release notes:
Bug Fixes
Contributors to this release
Full Changelog: axios/axios@v0.30.0...v0.30.1
v0.30.0Compare Source
Release notes:
Bug Fixes
Contributors to this release
Full Changelog: axios/axios@v0.29.0...v0.30.0
v0.29.0Compare Source
Release notes:
Bug Fixes
Contributors to this release
v0.28.1Compare Source
Release notes:
Release notes:
Bug Fixes
reqis not defined (#6307)v0.28.0Compare Source
Release notes:
Bug Fixes
withXSRFTokenoption to v0.x (#6091)Backports from v1.x:
axios.formToJSONmethod (#4735)url-encoded-formserializer to respect theformSerializerconfig (#4721)string[]toAxiosRequestHeaderstype (#4322)AxiosErrorstack capturing; (#4718)AxiosErrorstatus code type; (#4717)blobto the list of protocols supported by the browser (#4678)v0.27.2Compare Source
Fixes and Functionality:
v0.27.1Compare Source
Fixes and Functionality:
v0.27.0Compare Source
Breaking changes:
Content-Typerequest header when passing FormData (#3785)transformRequestandtoFormData(#4470)QOL and DevX improvements:
Fixes and Functionality:
Internal and Tests:
Documentation:
Notes:
v0.26.1Compare Source
Fixes and Functionality:
v0.26.0Compare Source
Fixes and Functionality:
v0.25.0Compare Source
Breaking changes:
Fixes and Functionality:
booleanandnumbertypes (#4144)undefined(#3153)Internal and Tests:
Documentation:
Huge thanks to everyone who contributed to this release via code (authors listed below) or via reviews and triaging on GitHub:
v0.24.0Compare Source
Breaking changes:
Huge thanks to everyone who contributed to this release via code (authors listed below) or via reviews and triaging on GitHub:
expressjs/express (express)
v4.22.1Compare Source
v4.22.0Compare Source
v4.21.2Compare Source
What's Changed
Full Changelog: expressjs/express@4.21.1...4.21.2
v4.21.1Compare Source
What's Changed
Full Changelog: expressjs/express@4.21.0...4.21.1
v4.21.0Compare Source
What's Changed
"back"magic string in redirects by @blakeembrey in #5935New Contributors
Full Changelog: expressjs/express@4.20.0...4.21.0
v4.20.0Compare Source
==========
depthoption to customize the depth level in the parserdepthlevel for parsing URL-encoded data is now32(previously wasInfinity)res.redirect\,|, and^to align better with URL specoptions.maxAgeandoptions.expirestores.clearCookiev4.19.2Compare Source
==========
v4.19.1Compare Source
==========
v4.19.0Compare Source
==========
v4.18.3Compare Source
==========
partitionedoptionv4.18.2Compare Source
===================
v4.18.1Compare Source
===================
v4.18.0Compare Source
===================
res.downloadoptionswithoutfilenameinres.downloadres.statusnull/undefinedasmaxAgeinres.cookieObject.prototypevalues in settings throughapp.set/app.getdefaultwith same arguments as types inres.formatres.sendhttp-errorsforres.formaterrorstrictpriorityoptionexpiresoption to reject invalid datesevalusage withFunctionconstructorprocessto check for listeners425 Unordered Collectionto standard425 Too Earlyv4.17.3Compare Source
===================
__proto__keysv4.17.2Compare Source
===================
undefinedinres.jsonpundefinedwhen"json escape"is enabledRegExpsres.jsonp(obj, status)deprecation messageres.isJSDocmaxAgeoption to reject invalid valuesreq.socketover deprecatedreq.connectionfirebase/firebase-functions (firebase-functions)
v3.24.1Compare Source
v3.24.0Compare Source
v3.23.0Compare Source
v3.22.0Compare Source
v3.21.2Compare Source
toJSONwas not defined inUserRecord(#1125).v3.21.1Compare Source
v3.21.0Compare Source
[@type](#1088)v3.20.1Compare Source
v3.20.0Compare Source
v3.19.0Compare Source
v3.18.1Compare Source
v3.18.0Compare Source
v3.17.2Compare Source
v3.17.1Compare Source
v3.17.0Compare Source
optionsproperty.v3.16.0Compare Source
firebase/firebase-tools (firebase-tools)
v9.23.3Compare Source
v9.23.2Compare Source
firebase init hosting:githubwith no Hosting config infirebase.json. (#3113)remoteconfig:getwas not fetching the latest version by default. (#3559)v9.23.1Compare Source
--projectflag duringinitwould not be recognized with a default project already set. (#3870)v9.23.0Compare Source
firebase deploy --only extensionsnow supports project specifc .env files. When deploying to multiple projects, param values that are different between projects can be put inextensions/${extensionInstanceId}.env.${projectIdOrAlias}and common param values can be put inextensions/${extensionInstanceId}.env.v9.22.0Compare Source
firebase ext:exportcommand, and addsextensionstofirebase deploy. See https://firebase.google.com/docs/extensions/reuse-project-config for more infomation on how to manage your extensions with these commands.initwould crash with multiple Hosting items selected (#3742).crashlytics:symbols:upload) to upload native symbol files, used in Android NDK crash symbolication.v9.21.0Compare Source
nodejs/node (node)
v14.21.3: 2023-02-16, Version 14.21.3 'Fermium' (LTS), @richardlauCompare Source
This is a security release.
Notable Changes
The following CVEs are fixed in this release:
More detailed information on each of the vulnerabilities can be found in February 2023 Security Releases blog post.
This security release includes OpenSSL security updates as outlined in the recent
OpenSSL security advisory.
This security release also includes an npm update for Node.js 14 to address a number
of CVEs which either do not affect Node.js or are low severity in the context of Node.js. You
can get more details for the individual CVEs in
nodejs-dependency-vuln-assessments.
Commits
97a0443f13] - build: build ICU with ICU_NO_USER_DATA_OVERRIDE (RafaelGSS) nodejs-private/node-private#3749e6221529b] - deps: cherry-pick Windows ARM64 fix for openssl (Richard Lau) #465660d5f86451d] - deps: update archs files for OpenSSL-1.1.1t (RafaelGSS) #465668c11d17b40] - deps: upgrade openssl sources to 1.1.1t (RafaelGSS) #46566224e93c9ef] - deps: upgrade npm to 6.14.18 (Ruy Adorno) #45936d73ea4de13] - doc: clarify release notes for Node.js 14.21.2 (Richard Lau) #45846f7892c16be] - lib: makeRequireFunction patch when experimental policy (RafaelGSS) nodejs-private/node-private#358fa115ee8ac] - module: protect against prototype mutation (Antoine du Hamel) #4400783975b7fb4] - policy: makeRequireFunction on mainModule.require (RafaelGSS) nodejs-private/node-private#358a5f8798d7a] - test: avoid left behind child processes (Richard Lau) #46276v14.21.2: 2022-12-13, Version 14.21.2 'Fermium' (LTS), @richardlauCompare Source
Notable Changes
OpenSSL 1.1.1s
This update is a bugfix release and does not address any security
vulnerabilities.
Root certificates updated to NSS 3.85
Certificates added:
A626340Certificates removed:
Time zone update to 2022f
Time zone data has been updated to 2022f. This includes changes to Daylight
Savings Time (DST) for Fiji and Mexico. For more information, see
https://mm.icann.org/pipermail/tz-announce/2022-October/000075.html.
Commits
436a596e99] - crypto: update root certificates (Luigi Pinca) #454904b422d34af] - deps: V8: cherry-pickd2db7fa(Richard Lau) #45785625f4bf3a9] - deps: update corepack to 0.15.1 (Node.js GitHub Bot) #4533148a9810de8] - deps: update corepack to 0.15.0 (Node.js GitHub Bot) #452359f4e64b603] - deps: update timezone to 2022f (Richard Lau) #45521f297b6bd21] - deps: update archs files for OpenSSL-1.1.1s (RafaelGSS) #4527211629fef15] - deps: upgrade openssl sources to 1.1.1s (RafaelGSS) #45272c3a90c4b44] - http2: fix memory leak when nghttp2 hd threshold is reached (rogertyang) #41502785dc3efee] - module: cjs-module-lexer WebAssembly fallback (Guy Bedford) #436122dbeb889f6] - node-api: handle no support for external buffers (Michael Dawson) #451815b2ea124f3] - test: add test to validate changelogs for releases (Richard Lau) #45325f13f889956] - test: add a test to ensure the correctness of timezone upgrades (Darshan Sen) #452995608e6fa72] - tools: update certdata.txt (Luigi Pinca) #45490d6f1d7107b] - tools: have test-asan use ubuntu-20.04 (Filip Skokan) #45581370a00f737] - tools: make license-builder.sh comply with shellcheck 0.8.0 (Rich Trott) #41258v14.21.1: 2022-11-04, Version 14.21.1 'Fermium' (LTS), @BethGriggsCompare Source
This is a security release.
Notable changes
The following CVEs are fixed in this release:
More detailed information on each of the vulnerabilities can be found in November 2022 Security Releases blog post.
Commits
2b433af094] - inspector: harden IP address validation again (Tobias Nießen) nodejs-private/node-private#354v14.21.0: 2022-11-01, Version 14.21.0 'Fermium' (LTS), @danielleadamsCompare Source
Notable changes
Commits
773f587912] - deps: cherry-pick libuv/libuv@3a7b955(Ben Noordhuis) #43950a1dea66956] - deps: cherry-pick libuv/libuv@abb109f(Ben Noordhuis) #4395098c49d81f5] - deps: update corepack to 0.14.2 (Node.js GitHub Bot) #4477518c43c8518] - deps: update timezone to tz2022e (Richard Lau) #45094a1f8e4db48] - deps: update corepack to 0.14.1 (Node.js GitHub Bot) #44704e55389ca86] - deps: update corepack to 0.14.0 (Node.js GitHub Bot) #445090227462418] - deps: update corepack to 0.13.0 (Node.js GitHub Bot) #44318ee24c320ea] - deps: update corepack to 0.12.3 (Node.js GitHub Bot) #4422928e9891449] - deps: update corepack to 0.12.2 (Node.js GitHub Bot) #44159b6972c9df2] - **depConfiguration
📅 Schedule: Branch creation - Between 12:00 AM and 03:59 AM, only on Monday ( * 0-3 * * 1 ) (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.